Skip to main content

Assignments

An assignment connects a policy profile to a workspace. Without an assignment, no policies run against a workspace.

The assignments page, listing which profiles run against which workspaces

Creating an Assignment

Navigate to PoliciesWorkspace AssignmentsAdd Assignment.

Each assignment requires:

FieldDescription
WorkspaceWhich workspace to monitor
Policy ProfileWhich profile's policies to run
Schedule (optional)When to suppress automated actions

A workspace can have multiple assignments, each with a different profile. This enables layered governance (e.g. a security profile and a cost optimization profile on the same workspace).

Bulk Assignment

Assign one profile to multiple workspaces at once:

  1. Go to PoliciesWorkspace Assignments
  2. Click Bulk Assign
  3. Select the profile and optionally a schedule
  4. Select the target workspaces
  5. Confirm

Manual vs. Automatic Assignments

SourceCreated ByBehavior
ManualUser actionPersists until manually removed
Tag ruleAutomated via tag rulesManaged by rule sync; may be created or removed automatically

Automatic assignments are linked to their tag rule and marked with assignment_source: tag_rule. They may be re-created on the next sync if you delete them manually.

Manual assignments are never affected by tag rule syncs.

Editing an Assignment

You can change the schedule on an existing assignment but not the profile or workspace. To change the profile, delete the assignment and create a new one.

Deleting an Assignment

Removing an assignment stops all policies for that profile-workspace pair. Historical findings and execution records are preserved.